Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CI/CD (Infrastructure) Bill of Material #10

Open
bajpaigarima opened this issue Mar 24, 2022 · 2 comments
Open

CI/CD (Infrastructure) Bill of Material #10

bajpaigarima opened this issue Mar 24, 2022 · 2 comments
Assignees
Labels
enhancement New feature or request

Comments

@bajpaigarima
Copy link
Collaborator

  • A CI/CD Bill of Materials can be used to support the systematic review of known security vulnerabilities in open source components and approval of each component’s

  • An CI/CD BOM is useful both to the builder (manufacturer) and the buyer (customer) of a software product

  • Cyber Supply Chain Management and Transparency Act of 2014[10] was US legislation that proposed to require government agencies to obtain SBOMs for any new products they purchase, so it can help CI/CD consumers and producers

@bajpaigarima bajpaigarima self-assigned this Mar 24, 2022
@bajpaigarima bajpaigarima added the enhancement New feature or request label Mar 24, 2022
@ixchelruiz ixchelruiz self-assigned this Mar 25, 2022
@kcollasarundell
Copy link

This would likely combine well with a post\subsection on transparency logs.
The ability to provide a historic tamper resistant view of not just the SBOM but attestations on testing, validation and build process. As well as combining with the automation to prevent unsigned resources from being run-able.

@agileguru agileguru self-assigned this Apr 22, 2022
@moise3 moise3 self-assigned this Apr 22, 2022
@bradmccoydev
Copy link
Member

@Saim-Safdar can help connect with Tracy Ragan and Steve Taylor on this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

6 participants